Configuration reference
The whole configuration lives in the file .env in the bundle folder. setup.sh creates it from .env.example, which documents every setting with comments. This page lists the settings in the same groups.
- Set by setup.sh means that
setup.shfills the value: secrets are generated once when empty, and derived values are rewritten from the public URL and the TLS mode on every run. Do not edit derived values by hand; runsetup.shinstead. - A setting shown as (commented out) is present in
.env.examplebut inactive until you remove the#.
Apply changes with docker compose up -d.
Releaseβ
| Setting | Default | Meaning |
|---|---|---|
GOAT_VERSION | the bundle's release | The GOAT version all images use. See Upgrades. |
GOAT_REGISTRY | ghcr.io/plan4better/goat | Where the GOAT images are pulled from, e.g. an internal mirror |
Public address and TLSβ
| Setting | Default | Meaning |
|---|---|---|
GOAT_PUBLIC_URL | asked by setup.sh | The URL users type into the browser, without a trailing slash |
GOAT_TLS | auto | auto, custom, internal or off; see HTTPS and addresses |
GOAT_ACME_EMAIL | empty | Optional contact for Let's Encrypt expiry notices (auto only) |
GOAT_TRUSTED_PROXIES | private_ranges | Addresses allowed to set X-Forwarded-* headers (your load balancer), as CIDRs separated by spaces |
GOAT_ADMIN_ALLOW_CIDRS | 0.0.0.0/0 ::/0 | Networks allowed to open the Keycloak admin console under /keycloak/admin |
GOAT_CA_BUNDLE | empty | Path inside the containers of an extra CA certificate (PEM) in ./certs; set by setup.sh in internal mode. See Company CA. |
GOAT_HTTP_PORT | 80 | Port for HTTP; set by setup.sh from the URL or --http-port |
GOAT_HTTPS_PORT | 443 | Port for HTTPS; set by setup.sh from the URL |
GOAT_HOSTNAME, GOAT_NETWORK_ALIAS, GOAT_SITE_ADDRESS, GOAT_HTTPS_PUBLISH, GOAT_KEYCLOAK_SSL_REQUIRED | Derived; set by setup.sh |
Profilesβ
| Setting | Default | Meaning |
|---|---|---|
COMPOSE_PROFILES | garage,keycloak | The bundled components to run: garage (object storage), keycloak (login server), backup (nightly backups) |
Authenticationβ
| Setting | Default | Meaning |
|---|---|---|
AUTH | True | True: users log in through Keycloak. False: no login, everybody acts as one built-in administrator (local and demo installs only). |
GOAT_ADMIN_EMAIL | asked by setup.sh | The first GOAT user, created in the bundled Keycloak on the first start |
GOAT_ADMIN_PASSWORD | set by setup.sh | Password of the first user |
REALM_NAME | goat | Keycloak realm GOAT uses |
KEYCLOAK_CLIENT_ID | goat | Keycloak client GOAT uses |
KEYCLOAK_CLIENT_SECRET | set by setup.sh | Secret of that client |
KEYCLOAK_ADMIN_PASSWORD | set by setup.sh | Password of the user admin in the Keycloak admin console |
KEYCLOAK_PROVISION_INVITED_USERS | true | Create the login account in Keycloak when someone is invited whose email has none yet |
KEYCLOAK_DB_PASSWORD | set by setup.sh | Database password of the bundled Keycloak |
KEYCLOAK_PUBLIC_URL, KEYCLOAK_INTERNAL_URL | (commented out) | Your own Keycloak; see Your own Keycloak |
Object storage (S3)β
| Setting | Default | Meaning |
|---|---|---|
S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY | set by setup.sh | Access key for the bundled Garage, or your own S3 key |
GARAGE_RPC_SECRET, GARAGE_ADMIN_TOKEN | set by setup.sh | Internal secrets of the bundled Garage |
S3_ENDPOINT_URL, S3_PUBLIC_ENDPOINT_URL, S3_REGION, S3_BUCKET_NAME, S3_FORCE_PATH_STYLE | (commented out) | Your own S3; see Your own S3 storage |
ASSETS_S3_ENDPOINT_URL, ASSETS_BUCKET_NAME, ASSETS_URL | (commented out) | The publicly readable bucket for avatars and images on your own S3 |
Databaseβ
The memory defaults suit a 16 GB machine. As a rule of thumb, set POSTGRES_SHARED_BUFFERS to about 1/4 and POSTGRES_EFFECTIVE_CACHE_SIZE to about 3/4 of the RAM you give PostgreSQL.
| Setting | Default | Meaning |
|---|---|---|
POSTGRES_PASSWORD | set by setup.sh | Password of the GOAT database |
WINDMILL_DB_PASSWORD | set by setup.sh | Password of the Windmill database |
POSTGRES_SHARED_BUFFERS | 1GB | PostgreSQL shared_buffers |
POSTGRES_EFFECTIVE_CACHE_SIZE | 3GB | PostgreSQL effective_cache_size |
POSTGRES_MAX_CONNECTIONS | 200 | PostgreSQL max_connections |
POSTGRES_POOL_SIZE | 5 | Connection pool size of the Core API |
POSTGRES_MAX_OVERFLOW | 10 | Extra connections the Core API may open beyond the pool |
Jobs (Windmill)β
| Setting | Default | Meaning |
|---|---|---|
WINDMILL_ADMIN_PASSWORD | set by setup.sh | Password of admin@windmill.dev in the Windmill interface |
GOAT_TOOLS_WORKERS | 2 | Number of analysis jobs that run in parallel; each tools worker may use up to 4 GB of RAM |
WINDMILL_LOCAL_PORT | 8110 | Port of the Windmill interface, bound to 127.0.0.1 only; see Windmill |
GOAT_BASE_DATA_URL | https://goat-base-data.plan4better.de/ | Source of the routing and public transport base data; see Routing base data |
Web app secretsβ
| Setting | Default | Meaning |
|---|---|---|
NEXTAUTH_SECRET | set by setup.sh | Signing key for the web app's login sessions |
Optional integrationsβ
| Setting | Default | Meaning |
|---|---|---|
NEXT_PUBLIC_MAPTILER_KEY | empty | MapTiler key for the satellite/hybrid basemap (hidden when empty) |
NEXT_PUBLIC_MAPBOX_TOKEN | empty | Mapbox token for the place search |
CATALOG_S3_BUCKET, CATALOG_S3_ENDPOINT_URL, CATALOG_S3_ACCESS_KEY_ID, CATALOG_S3_SECRET_ACCESS_KEY, CATALOG_S3_REGION | empty | The GOAT data catalog (read-only bucket with the harmonised datasets) |
GEOCODING_URL, GEOCODING_AUTHORIZATION | empty | Geocoding service used by analysis tools |
NEXT_PUBLIC_WEBSITE_URL | https://www.plan4better.de | Website link and feeds shown in the app |
NEXT_PUBLIC_STATUS_FEED_URL | empty | Status feed shown in the app |
NEXT_PUBLIC_DOCS_URL | https://goat.plan4better.de/docs | Documentation link in the app |
STATIC_ASSETS_URL | https://assets.plan4better.de | Product artwork: icons, default thumbnails, email images |
OTEL_ENABLED | false | Export traces, metrics and logs through OpenTelemetry |
OTEL_EXPORTER_OTLP_ENDPOINT | empty | Your OpenTelemetry (OTLP) endpoint |
Emailβ
See Email for how these work together.
| Setting | Default | Meaning |
|---|---|---|
SMTP_HOST | empty | Mail server; email is off while empty |
SMTP_PORT | 587 | Port of the mail server |
SMTP_SECURITY | starttls | starttls, ssl or none |
SMTP_USER, SMTP_PASSWORD | empty | Login; leave both empty for a relay without login |
SMTP_FROM | empty | Sender address; SMTP_USER when empty |
EMAILS_FROM_NAME | GOAT | Sender name |
SMTP_STARTTLS, SMTP_SSL | true, false | Derived from SMTP_SECURITY; set by setup.sh |
EMAIL_BRAND_NAME, EMAIL_LOGO_URL, EMAIL_CONTACT_URL, EMAIL_PRIVACY_URL | (commented out) | Optional branding: name, logo instead of the name, footer links |
Backupsβ
These apply when the backup profile is on; see Backups.
| Setting | Default | Meaning |
|---|---|---|
BACKUP_TIME | 02:30 | Time of the nightly backup (UTC) |
BACKUP_RETENTION_DAYS | 7 | Backups older than this many days are removed |